FIELD DEVICE WITH A SECURITY MODULE, RETROFIT MODULE FOR A FIELD DEVICE, METHOD FOR SETTING AN IT SECURITY LEVEL AND COMPUTER PROGRAM CODE

DE502020011320D1Active Publication Date: 2025-07-17VEGA GRIESHABER GMBH & CO
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
DE502020011320
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Filing Date
2020-05-05
Publication Date
2025-07-17
Estimated Expiration
2040-05-05

AI Technical Summary

Technical Problem

Existing field devices for process automation lack the ability to efficiently implement varying IT security levels, leading to increased device variants, high hardware costs, and unnecessary energy consumption, while existing solutions compromise operating convenience and efficiency.

Method used

A field device with a security module that includes functional units for multiple IT security levels, allowing a one-time selection and irreversible activation/deactivation of necessary units based on the selected level, ensuring energy efficiency and tailored security.

Benefits of technology

Enables flexible implementation of tailored IT security levels without compromising convenience or energy consumption, preventing unauthorized changes and ensuring consistent security performance.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Various types of field devices are known from the state of the art.

[0002] The term field device encompasses various technical devices that are directly related to a production process. Field devices can include, in particular, actuators, sensors, transducers, and / or evaluation devices.

[0003] In the terminology used in this application, higher-level units that are assigned to the control room area must be clearly distinguished from field devices.

[0004] To date, existing field devices for process automation have only featured manufacturer-specific devices and procedures for implementing IT security aspects. Recent legal requirements in various countries require the implementation of specified security levels (SLs) for critical infrastructure facilities (KRITIS).

[0005] Field devices have been reliably measuring process-relevant media variables in a wide variety of applications for many years as process measuring devices. In the early years of process control technology, the measured values ​​were usually transmitted in analog form using analog interfaces, such as a 4-20 mA interface, from a process measuring device to a higher-level unit, such as an evaluation device or a process control center. With the advent of digitalization, this standard was expanded to include additional digital signals, for example, according to the HART standard, which also enabled bidirectional communication between the process measuring device and the process control center. A characteristic of such process control systems, however, was that the systems were essentially operated in isolated mode.A connection between different process control systems at different locations or different companies or a connection of the systems to the World Wide Web was not planned.

[0006] In recent years, particularly with the approaches of the fourth industrial revolution (Industry 4.0), the need to link entire process control systems or even entire production sites through a higher degree of networking, for example via the World Wide Web, has become apparent. However, the associated networking of industrial IT systems and office IT systems is leading to a number of new challenges, particularly in the area of ​​IT security, which makes the further development of existing devices and components absolutely necessary.

[0007] Another area of ​​application arises from the recently available self-contained field devices, particularly self-contained sensors. Sensors, i.e. field devices, in this product family are characterized by particularly simple installation without the need for a communication or power cable. The measured values ​​​​determined by these field devices are typically transmitted to a cloud, i.e., to a server on the World Wide Web, using narrowband radio technology (LoRa, Sigfox, NB-IOT). Typical application scenarios for such field devices include areas such as flood forecasting, inventory management, or other decentralized measurement tasks. Due to their direct connection to the World Wide Web, such field devices are inherently exposed to a constant threat of hacker attacks from the Internet.

[0008] In order to ensure the availability of productive systems in the future, various industries are currently defining standards that aim to harden the components of process control systems with regard to their resilience against negligently or deliberately initiated external attacks, thus increasing the availability of field devices and thus ensuring the productivity of plant operators.

[0009] In addition, legislators are also formulating new requirements for operators and manufacturers of equipment aimed at making critical infrastructure facilities (KRITIS) such as energy (electricity, gas, oil), transport (air, rail, water, road), drinking water supply, and even digital infrastructure resilient to negligent or deliberate hacker attacks. One example of this is Directive 2016 / 1148 (NIS Directive), adopted by the European Parliament and now implemented into national law by the member states of the European Union.

[0010] Depending on the threat situation at the respective application location, the existing cyber security standards (e.g. IEC 62443, ISO 27001) require that the devices used there meet a standardized IT security level, also called Security Level (SL).

[0011] IEC 62443 (as of August 2013, for example) has defined the following security levels, which are classified according to the means available to the attacker, the material and financial resources available, the technical capabilities and the underlying motivation. Attacker's skills Medium resources skills motivation SL0 no risk of interference / manipulation SL1 accidental / incidental interference / manipulation SL2 simply limited generally low SL3 sophisticated medium domain-specific medium SL4 sophisticated extensive domain-specific high

[0012] The security level SL0 is a purely theoretical construct in which there is no risk of interference or manipulation and therefore no measures are necessary.

[0013] The security level SL1 describes the ability of a system to avoid accidental and unintentional impairment or manipulation.

[0014] The security level SL2 describes the ability of a system to defend against intentional manipulation by interested individuals and companies with generic security knowledge.

[0015] The security level SL3 describes the ability of a system to defend against deliberate manipulation by experts and companies who develop and implement effective, yet cost-oriented attack scenarios with clear goals.

[0016] The security level SL4 describes the ability of a system to fend off deliberate manipulation by organizations with experts who prioritize achieving the specifically selected attack target at almost any cost.

[0017] When implementing these security levels, individual security levels can be combined or additional security levels can be introduced as intermediate levels.

[0018] For manufacturers of field devices, especially for manufacturers of level and pressure sensors, these framework conditions create the need to implement the IT security requirements anchored in various (industry-specific) standards and laws in an appropriate manner during the development and later during the operation of the field devices through the interaction of appropriately implemented hardware and software components.

[0019] This implementation of expanded measures regularly requires the integration of additional hardware and / or software components into the field devices. This can sometimes significantly increase the energy consumption of the devices, which can shorten the service life or at least the intervals between required maintenance cycles, especially in the case of battery-operated field devices.

[0020] In addition, there is the problem that industry-specific standards with their respective IT security levels (SL) must be technically considered. Furthermore, the different regulations imposed by the legislature must be taken into account.

[0021] An obvious solution is to provide devices specifically for different industries, each of which technically takes into account the required, industry-specific IT security levels (SL). However, in order to be prepared for all possible use cases within a refinery, for example, different devices must be provided for each IT security level required by the customer. It is obvious that this approach massively increases the variety of device variants, thus making the economic development and production of corresponding field devices uneconomical. On the other hand, providing only a single industry-specific device that implements the highest security level would result in high hardware costs and high energy consumption, coupled with reduced ergonomics when operating the devices.

[0022] EP 3 451 215 A1 shows the features mentioned in the preamble of the independent claims.

[0023] Further prior art is known from DE 10 2016 110 723 A1 and EP 3 509 247 A1.

[0024] It is the object of the present invention to further develop a field device in such a way that the problems known from the prior art are reduced.

[0025] This object is achieved by a field device having the features of patent claim 1, a retrofit module having the features of patent claim 11 , a method having the features of patent claim 15 and a computer program code having the features of patent claim 21.

[0026] A field device according to the invention for process automation technology with field device electronics having at least one communication interface has a security module with a plurality of functional units for implementing a plurality of predetermined IT security levels of different levels, wherein the security module further has a selection element for selecting an IT security level, wherein, on the basis of the selection, the functional units necessary for implementing the selected IT security level are activated and unnecessary functional units are deactivated.

[0027] The basic idea of ​​the present invention is to design field devices in such a way that they are capable of implementing different predefined IT security levels.

[0028] The field device according to the invention can thus be used for more than one security level, allowing a security level tailored to the intended use and the resulting IT security requirements to be selected and used. This way, the user does not have to accept any unnecessary compromises in operating convenience. Furthermore, the field device always consumes only the energy required for the respective IT security level, so that energy-autonomous devices, in particular, do not consume unnecessary energy.

[0029] In this context, a plurality of functional units for implementing a plurality of predefined IT security levels means that at least two different IT security levels can be implemented by at least two functional units.

[0030] In this application, functional units are understood to mean functional blocks implemented in hardware and software that are crucial for compliance with the specified IT security levels. In particular, IT security levels of different levels differ in at least one functional unit, i.e., at least one functional unit is activated or deactivated to implement one IT security level, while at least one functional unit is deactivated or deactivated to implement another IT security level.

[0031] The IT security levels underlying this application may concern various aspects of IT security and may be implemented through various measures, which are summarized in the functional units in this application.

[0032] Aspects of IT security, as they can be implemented in the IT security levels subject to the application, include various levels of identification and authentication of users, devices and software, usage control, securing the communication of the field device with regard to authentication and integrity as well as, for example, required response times.

[0033] According to the invention, the security module is designed in such a way that a one-time selection of the IT security level is possible. In this context, this means that the IT security level can be selected once and is subsequently fixed, i.e., unchangeable. According to the invention, the IT security level can be selected once by the user. This means that the field device can have no IT security level as delivered, or it can have any IT security level specified by the manufacturer, which can then be changed once by the user.

[0034] A one-time user selection can, in particular, mean that a subsequent user change to the IT security level is not possible. In certain embodiments, a distinction can be made between a user change to the IT security level and an administrator change to the IT security level. This means that in one embodiment, it can be provided that an administrator can subsequently change the IT security level even after an initial setting during commissioning. However, it can be provided, for example, that this can only be done with a device-specific unlock code and / or with additional manufacturer approval in addition to authentication as an administrator.

[0035] To ensure that the field device can only be operated with the desired security level, the security module is designed according to the invention in such a way that a selection of the IT security level is possible and necessary when commissioning the field device.

[0036] In this way, the operator of a plant can be encouraged to select the appropriate security level when commissioning a new field device. This level is then configured and determined during commissioning. In addition to or as an alternative to the procedure described above, a subsequent change to the IT security level may require resetting the field device to its factory settings, i.e., to its delivery state, and thus requiring recommissioning.

[0037] To prevent manipulation, the security module can be designed in such a way that the IT security level can only be selected when the field device is put into operation for the first time.

[0038] This can be achieved, for example, by designing the selection element to be mechanically irreversible. A mechanically irreversible design of the selection element can be achieved, for example, by a suitable locking mechanism for a setting that has been made once. Such a locking mechanism can, for example, be designed in such a way that changing the selection element is only possible to achieve a higher IT security level. Alternatively, the selection element can also be mechanically fixed, e.g., glued or secured in some other way. Additionally or alternatively, a mechanical selection element can also have a predetermined breaking point, i.e. the selection element breaks off at this predetermined breaking point when the user sets the IT security level for the first time, thus making subsequent changes to the IT security level impossible.

[0039] Additionally or alternatively, the security module can be designed such that the selection of the IT security level is electronically irreversible. This can be achieved, for example, by interrupting the necessary electrical connections after the selection element has been read for the first time. This can be done, for example, by deliberately interrupting the fuses installed there or otherwise destroying the electrical readability of the selection element. Additionally or alternatively, when setting the IT security level, functional elements that are deactivated to implement the selected IT security level can be prevented from reactivation by permanently interrupting the electrical connection to these functional elements.

[0040] For example, to implement a specific IT security level, it may be specified that a radio interface be deactivated. In the previously described embodiment, reactivation of the radio interface can be prevented, for example, by permanently interrupting an electrical connection to the radio interface or by deliberately rendering a transmitting element dysfunctional.

[0041] Additionally or alternatively, the security module can be designed such that a selection of the IT security level is irreversible in terms of software. For example, a portion of a program code that implements reading the selection element and setting the IT security level can be deleted after the IT security level has been successfully set or otherwise modified in such a way that a further reading of the selection element is not possible. In this embodiment, the selection element could then be set to select a different IT security level than the set one—provided a change is not also prevented at this point. However, this modified selection is no longer read, and the IT security level is therefore not changed.

[0042] To ensure that a previously selected IT security level is at least not downgraded, i.e., that a lower IT security level is not subsequently selected, the field device can be provided with the lowest IT security level upon delivery and the security module can be designed in such a way that only an increase in the IT security level is possible. This functionality can be achieved both through a suitable hardware design, e.g., the selection element, and through a suitable software implementation.

[0043] Alternatively, it is also possible that the field device is delivered with the highest IT security level and only a reduction of the IT security level is possible.

[0044] The selection element can be implemented as a hardware switch, preferably as a slide switch or rotary switch. Such a hardware switch allows for intuitive and user-friendly selection of the IT security level. A hardware-implemented design of the selection element can provide effective protection against network-based attacks and thus contribute to securing the field device.

[0045] In another embodiment, the selection element can be implemented as a selection menu in the user interface of the field device. Typically, the commissioning process of a field device includes various parameterization steps, into which a selection of the IT security level can be seamlessly integrated in this way.

[0046] In one embodiment of the field device, the selection element can control a multiplexer that is connected to the functional units for implementing the IT security level, at least in the delivery state. In this way, the various functional units for implementing the IT security level can be activated or deactivated via a suitable control of the multiplexer.

[0047] Retrofit module for a field device of process automation technology with field device electronics with at least one communication interface, wherein the retrofit module has a security module, wherein the security module has a selection element for selecting an IT security level, wherein the field device electronics and / or the security module have a plurality of functional units for implementing a plurality of predetermined IT security levels of different levels, wherein the security module cooperates with the field device electronics in such a way that functional units necessary for the implementation are activated and / or functional units not necessary are deactivated.

[0048] A corresponding retrofit module thus enables the implementation of IT security levels of varying levels and the selection of a desired IT security level. The retrofit module can also implement IT security levels that the field device would not have been able to achieve without it.

[0049] Features of security levels enabled by the retrofit module can include, for example, a hardware- or software-based signature or encryption of communication, a hardware- or software-based implementation of a second factor for user authentication, or user management. Furthermore, such a retrofit module can also include a firmware update for the existing field device. Such a firmware update for the field device can, for example, ensure that the field device electronics - depending on the selected security level - only accepts certain communication paths, remote stations, or add-on modules, and / or prevents deinstallation of the retrofit module.

[0050] The retrofit module can - as already explained with regard to the field device according to the invention - have various mechanisms that ensure an irreversible determination of the security level.

[0051] In one embodiment, the retrofit module can include a crypto module for signing and / or encrypting data. The crypto module can implement software- or hardware-based data signing to ensure data integrity, i.e., protecting data from alteration, and / or data encryption to protect data from unauthorized access. This can be done both for local data storage and for transmission to a higher-level unit.

[0052] In a further embodiment, the retrofit module includes a communication module for transmitting data from the field device to a higher-level unit. Such a communication module can, for example, establish secure communication with other devices in a known manner. Alternatively, proprietary communication with other manufacturer-specific devices can also be established, thus ensuring secure communication.

[0053] In a further embodiment, the retrofit module includes an authentication module. An authentication module can, for example, implement user authentication and / or user administration as well as associated password management. User authentication can include not only authentication of operating personnel, but also authentication of approved operating devices and / or communication partners.

[0054] A method according to the invention for setting an IT security level in a process automation field device with a security module having a plurality of functional units for implementing a plurality of predefined IT security levels of varying levels, wherein the security module has a selection element for selecting an IT security level, comprises at least the following method steps: A desired IT security level is selected using the selection element. This can be implemented using appropriate hardware and / or software.

[0055] The selection element is then read out. This means that the selected IT security level is determined.

[0056] Based on the selected IT security level, i.e. the IT security level selected with the selection element, the functional units necessary for the implementation of the selected IT security level are then activated and / or unnecessary functional units are deactivated.

[0057] It should be noted at this point that activation and deactivation refer to the operation of the field device and, in this context, mean a persistent commissioning or decommissioning of the respective functional units. Deactivation, or in other words, switching off the entire field device, has no effect on the status of the functional units after the field device is switched on again.

[0058] In a preferred embodiment of the method, the IT security level can be set only once, preferably once when the field device is put into operation, more preferably once and necessarily when the field device is put into operation.

[0059] This prevents the IT security level, once set, from being subsequently changed, especially lowered. This makes it impossible for attackers to, for example, set a lower IT security level and exploit the then-applicable, lower security requirements, for example, to spy on data.

[0060] If an IT security level is set once and forcibly during commissioning of the field device, this ensures that the security level must be selected during commissioning and cannot be changed subsequently. If the field devices are used, for example, in critical infrastructure facilities (KRITIS), this prevents a field device from being operated without the IT security level set during commissioning.

[0061] A procedure in which the IT security level can only be set once is achieved by mechanically deactivating the selection element when the IT security level is selected for the first time. Thus, by mechanically deactivating the selection element, i.e., rendering it inoperative, subsequent changes to the IT security level are prevented.

[0062] Additionally or alternatively, the selection element can be electrically deactivated, allowing only a one-time setting of the IT security level. This can be achieved, for example, by cutting the electrical connections required for reading the selection element after the first reading. For example, fuses can be provided for this purpose, which are cut after the selection element has been read.

[0063] Another option that can be used in addition or alternatively in the process is to deactivate the selection element using software. This can be done, for example, by deactivating or deleting the code sections required for the selection element. Likewise, the selection element can be read by deactivating or deleting the necessary code elements. Another possibility is that the selection element can still be modified and read, but this has no effect on the set IT security level.

[0064] To prevent exploitation of the selectability of the IT security level, the method can be designed such that the field device has the lowest IT security level upon delivery, and this can only be increased during configuration. This prevents the IT security level from being lowered once selected, regardless of whether the IT security level can only be selected once.

[0065] In an alternative embodiment, the method can also provide that the field device has the highest selectable IT security level upon delivery and that this level can only be lowered.

[0066] A computer program code according to the invention for setting an IT security level in a field device of process automation with a security module is designed such that, when executed in a processor, it causes the processor to execute a method as described above.

[0067] The present invention will be explained in detail below using exemplary embodiments with reference to the accompanying figures. They show: Figure 1 shows a first embodiment of a field device according to the present application, Figure 2 shows a second embodiment of a field device according to the present application, Figure 3 shows a third embodiment of a field device according to the present application with a retrofit module and Figure 4 shows an embodiment of a method according to the present application.

[0068] The exemplary embodiments of field devices presented below show exemplary implementations for the implementation of IT security levels SL based on the definitions of the IEC 62443 standard. The examples are intended to be purely exemplary in nature to clarify the basic structures and processes, and generally include the transfer to other existing or future standards with comparable concepts for the standardized definition of security levels according to the understanding of the present invention.

[0069] Figure 1 shows a first embodiment of a field device 101 according to the present application. Figure 1 The illustration shown is purely schematic and shows only the components relevant for the selection and implementation of the IT security level.

[0070] The field device 101 is designed to record a process variable, for example a fill level, via a measuring interface 102 and to make it available to the outside via a wired communication interface 104 or a wireless interface 103. The field device 101 has a selection element 105, for example a slide switch with four selectable positions, for specifying an IT security level SL. A processor 106 of the field device 101 recognizes the IT security level SL specified by the user based on a position of the selection element 105 and activates the position of a multiplexer 107 belonging to the set IT security level SL, which is connected to functional units 108, 109, 110, 111. The functional units 108, 109, 110, 111 contain hardware and software elements which, in accordance with the underlying definition for the IT security levels, e.g.are necessary due to a standard in order to achieve one of the security levels, in the case of IEC 62443 one of the IT security levels, SL1, SL2, SL3 or SL4.

[0071] The principle of this application will be explained below using the example of user authentication.

[0072] In the basic position of slide switch 105, security level SL1 is specified, which corresponds to the lowest level of IT security. In the event of user access, the authentication module associated with SL1 in functional unit 108 is activated. This module contains a mechanism that only allows access to field device 101 if a user identifies and authenticates themselves with a (random) user name and password.

[0073] However, if the slide switch 105 is in the second position, the processor 106 detects IT security level SL2. In this case, a login request to gain access to the field device 101 is processed by the functional unit 109, which includes mechanisms for managing a predefined list of users with the associated passwords and individual access rights—i.e., user management.

[0074] If the slide switch 105 is positioned in the third position, IT security level SL3 is set. In this case, the associated functional unit 110 will grant access to the field device 110 upon a request from a trusted network 104 if a known user identifies themselves with their individual password. However, upon access from an untrusted network 103, the unit 110 will only grant access if a registered, authorized user can authenticate themselves via multi-factor authentication, for example, by entering a password and additionally applying an NFC chip with an electronic access code.

[0075] If slide switch 105 is in the fourth position, the highest IT security level is required. A login request in SL4 mode is processed by functional unit 111, which, regardless of the network 103, 104 from which a request originates, generally only allows access to field device 101 and its values ​​and settings via multi-factor authentication.

[0076] It should be noted at this point that activating a specific IT security level also enables and / or disables certain hardware units, which may be contained in functional units 108, 109, 110, and 111. For example, IT security levels SL3 and SL4 require the use of hardware-based authentication elements to fundamentally prevent possible manipulation by malware at this critical point, while software elements can perform this task in levels SL1 and SL2, which can contribute to energy savings.

[0077] It may be provided to deactivate insecure access points of the field device when a high IT security level is activated. For example, it may be provided to deactivate a wireless interface 103 when security level SL3 or SL4 is selected. It may also be provided that this deactivation is irreversible, for example, by deleting the associated software components or by cutting fuses in supply lines to these hardware units.

[0078] The above example shows that both the computing effort and the energy consumption as well as the ergonomics of the user interface can be directly influenced by the choice of the IT security level.

[0079] It should be noted at this point that, in addition to user registration, a multitude of other safety-critical use cases can be covered by corresponding regulatory requirements, e.g., standards and guidelines, and can be assigned corresponding minimum requirements with regard to technical implementation. The hardware and software units necessary to implement the minimum requirements can be integrated into the functional units 108-111. Furthermore, the multiplexer 107 can consist of hardware and software units. It can be provided that parts of the multiplexer 107 and the functional units 108-111, if these can be implemented in software, are implemented in the processor 106.

[0080] Specifying the IT security level SL with the slide switch 105 can, in itself, pose a security risk. Therefore, it may be possible to implement other selection elements 105, for example, lockable selectors that can only be changed by service personnel authorized by the manufacturer. However, it may also be possible to make the selection element 105 accessible to the customer and, after the IT security level SL has been set, to protect it against unauthorized modification, for example, by means of a locking element 112 or by irreversibly breaking off the sliding element 105 at a predetermined breaking point.

[0081] It can also be provided to implement the selection element 105 via a software interface. In one embodiment, access to this element can be restricted to the initial commissioning of a field device 101 after delivery from the factory. In another embodiment, it can be provided that the sensor 101 always leaves the factory at the highest security level SL4, and a user is only able to change the positioning of the software-implemented selection element 105 after correspondingly extensive identification and authentication. It can also be provided to deliver the device 101 with a lower security level in order to only allow a change in the security level to a higher level of IT security after authentication has been completed.

[0082] It may be provided to allow a change to the selection element 105 only before or during initial commissioning. This can be achieved, for example, by irreversibly interrupting a connecting line 113 after the position of the selection element 105 has been read by the processor 106, for example by deliberately blowing a fuse in the connecting line 113. Additionally and / or alternatively, it may be provided to irreversibly deactivate the functional elements 108, 109, 110, 111 that are no longer required according to the required security level by blowing fuses in the connecting lines 114, 115, 116. It may also be provided to irreversibly and permanently delete unnecessary software elements in the functional elements 114, 115, 116, 117 or to irreversibly interrupt the supply lines to the memory elements containing the software elements.

[0083] Figure 2shows a second embodiment of a field device 201 according to the present application. The basic idea of ​​this embodiment is to integrate the need to activate an IT security level SL required for the respective application directly into the field device 201 according to the invention, i.e. to make a mandatory selection of an IT security level when commissioning the field device 201. Customers of process measuring devices already have the option of defining the most important operational parameters of a device by using a commissioning wizard or via corresponding input masks on PCs or apps or display and operating modules. An application unit 202 can be used for this purpose, for example. The application unit 202 can, for example, be designed to record the country of commissioning (often combined with the selection of the language of the display units) and the respective industry of the operator.From this and any other requested information, the security level determination device 203 built into the field device 201 can independently determine which security level SL is appropriate for the respective application. For example, during commissioning in a European country within a drinking water reservoir, the field device 201 can independently determine that operation within a facility of a critical infrastructure facility (KRITIS) is desired, which may, for example, require operation at IT security level SL3. By controlling the security level selector 203, the required security level SL can be determined according to the principles of the already described in connection with the . Figure 1 associated processes can be set.

[0084] Often, industry-specific or national standards (e.g. IEC 62443-1-1) require not only IT security, but also robustness of devices against unauthorized access, as well as reliable function and continuous availability of the device function, especially in critical infrastructure facilities (KRITIS). Therefore, both in the example of the Figure 1 as well as in the embodiment of the Figure 2 In addition, provision should be made to activate hardware and software units that increase the functional safety of the devices (e.g. according to IEC 61508) to a predefined level.

[0085] Figure 3 shows a third embodiment of a field device 301 with a retrofit module 302.

[0086] The Figure 3The field device 301 shown thus discloses a possibility for retrofitting an existing field device 301 that did not previously have predefined IT security levels SL. Such field devices 301 have been produced for many years, and it is a challenge for the manufacturers of the field devices 301 to equip existing devices with extended IT security levels SL. In a large number of devices, potential IT-relevant security attacks can essentially only occur via a wired interface 303. One approach is therefore to separate a communication line 303 of the field device 301 and install a retrofit module 302 with a security module for implementing corresponding IT security levels SL, which can be accommodated, for example, in a second chamber of a housing of the field device 301.The retrofit module 303 can be suitably configured to have a wired output line 304 of a predefined length, which is designed to connect to an original contact interface 305 of the existing field device 301. Additionally or alternatively, the retrofit module 302 can be permanently attached to the field device 301, for example, by means of safety screw connectors 306 that can be fixed with adhesive. Furthermore, it can be provided to replace an original housing cover (not shown) with a self-adhesive and thus irremovable housing cover 307.

[0087] Depending on the required IT security level (SL), the retrofit module 302 performs a variety of security functions for the field device 301, such as user management, authentication, encryption, or other functions that may be required by the respective standard according to the desired IT security level (SL). In particular, the retrofit module 302 can also act as a firewall, continuously monitoring incoming data packets and rejecting them if necessary.

[0088] Depending on the desired IT security level SL, various retrofit modules 302 can be provided for retrofitting at the customer's site or in the factory. It can also be provided to design the retrofit module 302 such that it can be adjusted according to the above embodiments, thus implementing different IT security levels.

[0089] A field device 301 retrofitted in this way can then only be accessed from the outside via the communication line 303 using the retrofit module 302 and the security module contained therein. Unauthorized access and tampering at the installation site can be reliably prevented by gluing the sensor cover 307.

[0090] Figure 4 shows in a flowchart a possible embodiment of a method 400 for setting an IT security level SL according to the present application.

[0091] Figure 4 schematically illustrates the sequence of the method 400 and in particular does not exclude the insertion of further method steps for setting the IT security level SL or for operating the field device 101, 201, 301.

[0092] In a first step 401, the commissioning of the field device 101, 201, 301, which is configured according to one of the preceding Figures 1 to 3 can be designed, has begun.

[0093] During the commissioning process, the user is prompted in a step 402 to select an IT security level SL, for example according to the four IT security levels SL1, SL2, SL3 and SL4 described above, and to confirm this selection if necessary.

[0094] In a step 403, the IT security level SL is selected using the selection element 105, and in a subsequent step 404 the selection element 105 is read out.

[0095] Depending on the selected and read IT security level SL, in a further step 405, the functional units 108-111 required for the implementation of the selected IT security level SL are activated, and the functional units 108-111 not required for the implementation are deactivated. Non-required functional units expressly include the functional units that must be deactivated for the implementation of the selected IT security level SL, e.g., the deactivation of a radio unit.

[0096] In the presently presented embodiment of a method 400 for setting an IT security level SL, the selection element 105 is deactivated in a further step 406. This can be done, for example, when implementing the method in software, by deleting or otherwise making inaccessible corresponding program parts.

[0097] After setting the selected IT security level SL, the field device is operated at the selected IT security level.

Claims

1. A process automation technology field device having field device electronics with at least one communication interface, the field device having a security module with a plurality of functional units for implementing a plurality of predetermined IT security levels of different grades, the functional units being configured as function blocks that are implemented in hardware and software, and the functional units containing hardware elements and software elements, the security module having a selection element for user selection of an IT security level, the functional units necessary for implementing the selected IT security level being activated and unnecessary functional units being deactivated on the basis of the selection, characterized in that the security module is designed in such a manner that the selection of the IT security level is possible and required once during commissioning of the field device.

2. The field device according to Claim 1, characterized in that the security module is configured in such a manner that the selection of the IT security level is possible during initial commissioning of the field device exclusively.

3. The field device according to one of the preceding claims, characterized in that the selection element is configured in a mechanically irreversible manner.

4. The field device according to one of the preceding claims, characterized in that the security module is configured in such a manner that the selection of the IT security level is electronically irreversible.

5. The field device according to one of the preceding claims, characterized in that the security module is configured in such a manner that the selection of the IT security level is irreversible in terms of software technology.

6. The field device according to one of the preceding claims, characterized in that the field device has the lowest IT security level upon delivery and the security module is configured in such a manner that an increase of the IT security level is possible exclusively.

7. The field device according to one of Claims 1 to 5, characterized in that the field device has the highest IT security level upon delivery and the security module is configured in such a manner that a lowering of the IT security level is possible exclusively.

8. The field device according to one of the preceding claims, characterized in that the selection element is designed as a hardware switch, preferably as a slide switch or rotary switch.

9. The field device according to one of the preceding claims, characterized in that the selection element is designed as part of a user interface of the field device.

10. The field device according to one of the preceding claims, characterized in that the selection element activates a multiplexer, which is connected to the functional units for implementing the IT security level.

11. A retrofitting module for a process automation technology field device having field device electronics with at least one communication interface, the retrofitting module having a security module, the security module having a selection element for user selection of an IT security level, the field device electronics and / or the security module having a plurality of functional units for implementing a plurality of predetermined IT security levels of different grades, the functional units being configured as function blocks that are implemented in hardware and software, and the functional units containing hardware elements and software elements, the security module cooperating with the field device electronics in such a manner that functional units necessary for the implementation are activated and unnecessary functional units are deactivated, characterized in that the security module is designed in such a manner that the selection of the IT security level is possible and required once during commissioning of the field device.

12. The retrofitting module according to Claim 11, characterized in that the retrofitting module has a cryptomodule for signing and / or encrypting data.

13. The retrofitting module according to either of Claims 11 and 12, characterized in that the retrofitting module has a communication module for transmitting data of the field device to a superordinate unit.

14. The retrofitting module device according to one of Claims 11 to 13, characterized in that the retrofitting module has an authentication module.

15. A method for setting an IT security level in a process automation field device having a security module with a plurality of functional units for implementing a plurality of predetermined IT security levels of different grades, the functional units being configured as function blocks that are implemented in hardware and software, and the functional units containing hardware elements and software elements, and the security module having a selection element for selecting an IT security level, having the steps: - selecting a desired IT security level by means of the selection element, - reading the selection element, - activating necessary functional units and deactivating unnecessary functional units for implementing the selected IT security level, characterized in that setting of an IT security level is carried out only once during commissioning of the field device.

16. The method according to Claim 15, in which setting of an IT security level is carried out once and compulsorily during commissioning of the field device.

17. The method according to Claim 16, in which the setting of the IT security level is only possible once, in that the selection element is mechanically deactivated.

18. The method according to either of Claims 16 and 17, in which the setting of the IT security level is only possible once, in that the selection element is electrically deactivated.

19. The method according to one of Claims 16 to 18, in which the setting of the IT security level is only possible once, in that the selection element is deactivated using software.

20. The method according to one of Claims 16 to 19, in which the field device has the lowest IT security level upon delivery and this can only be increased during setting.

21. A computer program code for setting an IT security level in a process automation field device having a security module, which, when it is executed in a processor, causes the same to execute a method according to one of Claims 16 to 21.